/ Trust
Trust & Security
This page is maintained by ThebinderLab to answer common security and privacy questions about our shop. It describes current practices and is not an independent certification.
Shared responsibility
ThebinderLab AB operates the storefront and is responsible for how we collect and handle your data. Our hosting and database providers run the underlying infrastructure. You are responsible for keeping your account credentials safe.
Payments
All card payments are processed by Stripe. We never see or store full card numbers, CVCs, or bank credentials. Stripe is PCI-DSS Level 1 certified.
Data in transit and at rest
The site is served over HTTPS. Customer and order data is stored in a managed Postgres database with encryption at rest provided by our hosting partner.
Access control
Customer-facing data is protected by row-level security policies in our database, so users only access their own orders and account information. Administrative access is limited to a small number of ThebinderLab staff.
Subprocessors
We share data only with the processors we need to run the shop: Stripe (payments), Resend (transactional email), our print and shipping partners, and our hosting / database provider. We do not sell personal data.
Cookies and analytics
Strictly necessary cookies are always on. Analytics and marketing cookies only run after you consent via our cookie banner.
Retention and deletion
Order and tax records are retained for 7 years to meet Swedish legal requirements. Marketing opt-ins are kept until you unsubscribe. See our Privacy Policy for full details and how to request deletion.
Report a vulnerability
If you believe you have found a security issue, please email security@thebinderlab.com. We appreciate responsible disclosure and will respond as quickly as we can.